- It's unreasonable to expect people to pay the full price for minor security fixes that still need to go out
- Because security upgrades are invisible to the user, it may be harder for the customer to see their value v. new features
- The timeline of when security updates need to go out is less predictable than that of feature upgrades, resulting in unpredictable revenue and expenditure for both the vendor and the customer and the customer may not have the budget to pay for an unexpected security fix
- Customers often want to take time to consider whether it is worth paying for upgrades, whereas security fixes should be applied as soon as possible
- The vendor must invest a lot of resources in testing the security of their software even when no security upgrades are warranted